Important Detection 2026: Ransomware Shadow Copy and Backup Deletion (T1490)
Detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to delete volume shadow copies, backup catalogs, or disable recovery mechanisms. This behavior is commonly associated with ransomware or destructive attacks attempting to inhibit system recovery.
Sigma

